|Number of vulnerabilities||1|
|CVE ID|| CVE-2018-8373
|CWE ID|| CWE-416
|Public exploit||This vulnerability is being exploited in the wild.|
Microsoft Internet Explorer
Client/Desktop applications / Web browsers
This security advisory describes one critical risk vulnerability.
CWE-416 - Use After Free
Exploit availability: NoDescription
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a use-after-free error in VBScript when the scripting engine handles objects in memory in Internet Explorer. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note: The vulnerability has been exploited in the wild.Mitigation
Install updates from vendor's website.Vulnerable software versions
Microsoft Internet Explorer: 9, 10, 11CPE
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to trick the victim to visit a specially crafted website.
Is there known malware, which exploits this vulnerability?
Yes. This vulnerability is being exploited in the wild.